I get that it is hard to admit responsibility, but this is ridiculous...
Imagine you get an email that appears at first glance to be from your spouse, it mentions your kids by name, and it also mentions that the spouse ran the numbers on your upcoming refinance and can you check the math in the spreadsheet she just attached. Assuming the attacker did their homework (i.e., names were right, you actually are going through a refinance, etc) there's a good chance even savvy users will open that excel file.
Good luck.
no default downloading, cannot execute anything downloaded
2. What if you just click on a link? Browser exploits are a thing too
good luck :)
And you don't need to persist anything to disk, just get a key logger going in memory. Or scrape the data from your other processes. Once you get arbitrary code execution on the machine it's game over.
Seriously, I deal with this kind of stuff for a living. No one is immune to these kinds of attacks; not you, not me, not anyone.
and you know that how?
I have no idea as to what went on with the specifics of this recent french "hack".
Not quite. The IT aide did say that the email (which was an imitation of a real "You've already been hacked" email template) was legitimate, but did not directly recommend clicking on links in the email.
He recommended visiting a correct URL. He should have said "I'm not sure, but don't click; to be safe, go to this URL instead"
Amusingly, the IT guy uses bit.ly for his surveys, and the phishing link was also a bit.ly link.
These phishing attempts are definitely very sophisticated. Have you read the Trend Micro report? https://documents.trendmicro.com/assets/wp/wp-two-years-of-p...